cgr.dev/chainguard/python:latest
SCOUT
A score 100
docker pull cgr.dev/chainguard/python:latest click to select Image metadata
PULL COUNT
—
repository-level (not per-tag)
SIZE (COMPRESSED)
27 MB
ARCHITECTURES
2
RUNS AS
non-root
image config.User
LAST PUSHED
yesterday
2026-10-09 12:30:54
MANIFEST DIGEST
from registry manifest
Latest scan
2026-10-10 01:40:29 UTC · todayOPEN CVES BY SEVERITY
0
CRITICAL
0
HIGH
2
MEDIUM
0
LOW/NEG
Grype DB
2026-10-09T06:32:32.000Z
· rubric cerodeo-v1 RUBRIC BREAKDOWN (7 signals that moved the score)
+10 · Runs as non-root +10 · Rebuilt in last 90 days +5 · Cosign signature +5 · SLSA provenance +5 · SLSA subject matches digest +2 · Multi-arch +3 · Signed SBOM attestation
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh cgr.dev/chainguard/python:latest \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z